Cybersecurity-Apprentice · domain
Cloud Security
Practise Certified Cybersecurity Apprentice (Cybersecurity-Apprentice) Cloud Security practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Cloud Security questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Cloud Security
Watch out for
Common Cloud Security exam traps
Question index
All Cloud Security questions (26)
Click any question to see the full explanation, or start a practice session above.
A security operations team is investigating an incident where an attacker compromised cloud credentials and attempted privilege escalation. Which THREE Prisma Cloud features or data sources assist in detecting and investigating this cloud security incident? (Choose three)
Hard2Under the shared responsibility model in cloud computing, the customer retains responsibility for securing specific layers regardless of whether the service is IaaS, PaaS, or SaaS. Which TWO items are always the customer's responsibility? (Choose two)
Easy3An administrator needs to restrict access to the Prisma Cloud administrative console based on corporate IP ranges. Where within the Prisma Cloud platform should the administrator configure trusted IP address restrictions?
Medium4A junior cloud engineer is configuring a new AWS S3 bucket and wants to ensure that Prisma Cloud successfully detects public exposure risks. Which Prisma Cloud feature continuously evaluates cloud resource configurations against security benchmarks like CIS?
Easy5A security architect is designing an enterprise logging strategy where all Prisma Cloud audit alerts, vulnerability findings, and compliance violations must be streamed to a third-party SIEM (such as Splunk). Which Prisma Cloud feature should be configured to achieve real-time log export?
Hard6A security administrator is evaluating cloud environments and needs to determine where customer responsibility ends in an Infrastructure as Service (IaaS) model. Which component is managed entirely by the cloud provider in IaaS?
Easy7A security engineer is configuring Prisma Cloud Compute runtime defense rules for containerized workloads. Which THREE runtime behaviors can Prisma Cloud Compute monitor and defend against? (Choose three)
Medium8An enterprise security architect is reviewing Prisma Cloud integration options for securing cloud-native applications throughout their lifecycle. Which THREE activities are supported by Prisma Cloud Application Security (IaC Security)? (Choose three)
Hard9An application security engineer configures Prisma Cloud WAAS (Web Application and API Security) to protect a containerized microservices application running behind an ingress controller. Which deployment method is supported for WAAS in a Kubernetes environment?
Hard10An administrator is reviewing the core components and capabilities of Prisma Cloud Cloud Security Posture Management (CSPM). Which TWO capabilities are primary functions of Prisma Cloud CSPM? (Choose two)
Easy11An administrator is deploying Prisma Cloud to secure a multi-cloud environment consisting of AWS and Azure. The administrator needs to understand the boundaries of security management under the shared responsibility model. Which responsibility always remains with the customer regardless of the cloud service model used?
Easy12A DevOps engineer observes that Prisma Cloud Compute vulnerability scans are reporting high severity Common Vulnerabilities and Exposures (CVEs) on running containers, but the build pipeline failed to catch them. How should the engineer integrate Prisma Cloud into the CI/CD pipeline to prevent vulnerable images from being built and pushed?
Hard13An auditor requests evidence that public AWS S3 buckets are automatically remediated when discovered by Prisma Cloud. Which feature should the security engineer configure to achieve automated remediation?
Medium14An enterprise security team wants to prevent developers from deploying Infrastructure as Code (IaC) templates that contain misconfigurations, such as open security groups. Which Prisma Cloud module should be integrated into the developer workflow (e.g., GitHub or Terraform Cloud)?
Medium15An enterprise security team deploys Prisma Cloud Compute across their Kubernetes clusters to enforce security policies. A developer attempts to deploy a privileged pod that violates runtime security policies. Which Prisma Cloud component intercepts and blocks this deployment at the admission controller level?
Medium16A security analyst receives a Prisma Cloud alert regarding suspicious API activity in an AWS account, indicating potential credential compromise. Which Prisma Cloud module generated this alert by analyzing cloud provider audit logs for anomalous behavior?
Medium17A security architect is configuring CloudTrail integration for Prisma Cloud across multiple AWS accounts managed through AWS Organizations. Which account deployment method should be used to ensure centralized log ingestion and security posture visibility?
Medium18An administrator is configuring Prisma Cloud Compute defense mechanisms for serverless functions (FaaS) such as AWS Lambda. Which THREE capabilities does Prisma Cloud provide for serverless security? (Choose three)
Hard19An administrator is reviewing Prisma Cloud agentless scanning capabilities for AWS EC2 instances. What is the primary advantage of utilizing agentless scanning compared to deploying the traditional Defender agent on every workload?
Medium20An auditor notices that a cloud account onboarded to Prisma Cloud has generated numerous alerts for unused IAM access keys. Which underlying Prisma Cloud data source is evaluated to detect this condition?
Hard21A compliance officer needs to verify whether cloud storage buckets across AWS and Azure meet corporate encryption standards. Which Prisma Cloud module provides out-of-the-box compliance reporting against standards such as HIPAA and PCI-DSS?
Easy22A security analyst is reviewing compliance posture using Prisma Cloud Compute and needs to secure cloud workloads. According to the shared responsibility model for a containerized application running on AWS Elastic Kubernetes Service (EKS), who is responsible for patching the container OS base image?
Easy23A security engineer is writing a custom RQL (Resource Query Language) search in Prisma Cloud to find all AWS EC2 instances that do not have encryption enabled on their root volumes. Which RQL query syntax is correct?
Medium24An enterprise has strict compliance requirements requiring visibility into network traffic flows between Kubernetes pods across different namespaces. Which Prisma Cloud Compute feature should be enabled to monitor and enforce layer 7 network segmentation rules inside the cluster?
Hard25When onboarding multi-account cloud environments into Prisma Cloud, administrators can choose from several integration methods. Which THREE advantages are gained by setting up centralized cloud account onboarding and role aggregation? (Choose three)
Medium26An administrator needs to onboard a new Google Cloud Platform (GCP) organization into Prisma Cloud with least-privilege permissions. Which GCP authentication method does Prisma Cloud recommend and support for secure API integration?
HardOther domains
All Cybersecurity-Apprentice exam domains
Frequently asked questions
- What does the Cloud Security domain cover on the Cybersecurity-Apprentice exam?
- Cloud concepts questions usually test the service model (IaaS/PaaS/SaaS) and deployment model (public/private/hybrid/community) appropriate for a given scenario.
- How many questions are in this domain?
- This page lists all 26 Cloud Security questions in the Cybersecurity-Apprentice question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Cloud Security questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.